Researchers warn of Safari zero-day exploit targeting Apple iPhones
Summary
Researchers have warned that hackers are actively exploiting a zero-day vulnerability in Safari on Apple iPhones, targeting cryptocurrency-related data such as private keys and recovery phrases. This attack begins when users visit a malicious webpage, utilizing memory corruption in WebKit and JavaScriptCore to bypass security measures and gain kernel-level access. Security experts are urging iPhone users to urgently update their iOS to mitigate these risks and protect sensitive information stored on their devices.
Analysis
Apple: Apple Inc. is the technology company responsible for the iPhone, iOS operating system, and integrated software services. It is central to the reported incident as its devices and browser are the targets of an active zero-day exploit chain affecting Safari on iPhones. Recent researcher disclosures emphasize the importance of timely iOS security updates to mitigate such threats. Safari: Safari is Apple's web browser and the primary interface for WebKit on iOS devices. The news describes it as the entry point for a sophisticated exploit that begins with visiting a malicious webpage and escalates to extract private keys, seed phrases, and Keychain data. Security researchers have highlighted this vector in urgent public warnings issued within the past week. Exploitation Vector: The attack initiates when a user visits a malicious webpage in Safari, leveraging memory corruption in WebKit and JavaScriptCore to bypass security features and reach kernel-level access. Mitigation Emphasis: Researchers from security firms and industry executives are actively urging iPhone users to apply the latest iOS updates immediately to address the disclosed vulnerabilities. Crypto-Specific Risk: The exploit specifically targets cryptocurrency-related data stored on the device, including wallet private keys and recovery phrases, bypassing typical app-level protections.
Categories
techcrypto
Related sources
- https://mallory.ai/stories/019f1793-08da-7143-8807-7a2ad0c3c3d3
- https://csirt.ncc.gov.ng/index.php/resources/security-advisories/412-apple-fixes-webkit-vulnerability-that-could-allow-malicious-websites-access-user-data
- https://www.panews.io/articles/01a0b944-dc0b-7425-8c59-3d26313565d5
- https://blockchainreporter.net/slowmist-warns-of-ios-exploit-stealing-wallet-keys/
- https://www.sentinelone.com/vulnerability-database/cve-2026-43715/
- https://u.today/visit-website-and-lose-your-crypto-ledger-exec-issues-warning-about-safari-attack
- https://www.malwarebytes.com/blog/news/2026/06/update-time-apple-releases-security-patches-for-ios-macos-tahoe-safari
- https://www.weex.com/weexview/detail/slow-fog-warns-ios-attack-chain-can-steal-wallet-data-go4zwhc9g6ytxliya57g67vk
- https://thehackernews.com/2026/06/apple-patches-30-ios-macos-safari-flaws.html